All Projects → devanshbatham → Awesome Bugbounty Writeups

devanshbatham / Awesome Bugbounty Writeups

A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference

Programming Languages

python
139335 projects - #7 most used programming language

Projects that are alternatives of or similar to Awesome Bugbounty Writeups

DeadDNS
DNS hijacking via dead records automation tool
Stars: ✭ 44 (-98.19%)
Mutual labels:  bugbounty, bughunting, bugbountytips
Howtohunt
Tutorials and Things to Do while Hunting Vulnerability.
Stars: ✭ 2,996 (+23.34%)
Mutual labels:  bugbounty, bugbountytips, bughunting-methodology
WDIR
Good resources about web security that I have read.
Stars: ✭ 14 (-99.42%)
Mutual labels:  bugbounty, bugbountytips, bugbounty-writeups
CVE-2021-44228-PoC-log4j-bypass-words
🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks
Stars: ✭ 760 (-68.71%)
Mutual labels:  bugbounty, bugbounty-writeups, security-writeups
HolyTips
A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
Stars: ✭ 1,210 (-50.19%)
Mutual labels:  bugbounty, bugbountytips, bugbounty-writeups
SQLi-Query-Tampering
SQLi Query Tampering extends and adds custom Payload Generator/Processor in Burp Suite's Intruder. This extension gives you the flexibility of manual testing with many powerful evasion techniques.
Stars: ✭ 123 (-94.94%)
Mutual labels:  bugbounty, bughunting
BugBounty CheatSheet
BugBounty_CheatSheet
Stars: ✭ 113 (-95.35%)
Mutual labels:  bugbountytips, bugbounty-writeups
nerdbug
Full Nuclei automation script with logic explanation.
Stars: ✭ 153 (-93.7%)
Mutual labels:  bugbounty, bugbountytips
Galaxy-Bugbounty-Checklist
Tips and Tutorials for Bug Bounty and also Penetration Tests.
Stars: ✭ 34 (-98.6%)
Mutual labels:  bugbounty, bugbountytips
hack-pet
🐰 Managing command snippets for hackers/bug bounty hunters. with pet.
Stars: ✭ 77 (-96.83%)
Mutual labels:  bugbounty, bugbountytips
cf-check
CloudFlare Checker written in Go
Stars: ✭ 147 (-93.95%)
Mutual labels:  bugbounty, bugbountytips
awesome-list-of-secrets-in-environment-variables
🦄🔒 Awesome list of secrets in environment variables 🖥️
Stars: ✭ 538 (-77.85%)
Mutual labels:  bugbounty, security-writeups
Defaultcreds Cheat Sheet
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️
Stars: ✭ 1,949 (-19.76%)
Mutual labels:  bugbounty
Quiver
Quiver is the tool to manage all of your tools for bug bounty hunting and penetration testing.
Stars: ✭ 140 (-94.24%)
Mutual labels:  bugbounty
Grecon
Your Google Recon is Now Automated
Stars: ✭ 119 (-95.1%)
Mutual labels:  bugbounty
Corsme
Cross Origin Resource Sharing MisConfiguration Scanner
Stars: ✭ 118 (-95.14%)
Mutual labels:  bugbounty
Proof Of Concepts
A little collection of fun and creative proof of concepts to demonstrate the potential impact of a security vulnerability.
Stars: ✭ 148 (-93.91%)
Mutual labels:  bugbounty
Nosqlmap
Automated NoSQL database enumeration and web application exploitation tool.
Stars: ✭ 1,928 (-20.63%)
Mutual labels:  bugbounty
Hackeronedb
The unofficial HackerOne disclosure Timeline
Stars: ✭ 117 (-95.18%)
Mutual labels:  bugbounty
Quickxss
Automating XSS using Bash
Stars: ✭ 113 (-95.35%)
Mutual labels:  bugbounty

Want to support my work?

If you think my work has added some value to your existing knowledge, then you can Buy me a Coffee here (and who doesn't loves a good cup of coffee?')

name

Contents

Cross Site Scripting (XSS)

Cross Site Request Forgery (CSRF)

Clickjacking (UI redressing attack)

Local File Inclusion (LFI)

Subdomain Takeover

Denial of Service (DOS)

Authentication Bypass

SQL Injection(SQLI)

Insecure Direct Object Reference (IDOR)

2FA related issues

CORS related issues

Server Side Request Forgery (SSRF)

Race Condition

Remote Code Execution (RCE)

Buffer Overflow Writeups

Android Pentesting

Contributing

  • Open Pull Requests
  • Send me links of writeups to My Twitter : 0xAsm0d3us

Maintainers

This Repo is maintained by :

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].